WhisperX tag archive

#authentication flaw

This page collects WhisperX intelligence signals tagged #authentication flaw. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-03-25 18:27:32 · GitHub Issues

1. Critical API Flaw Exposes Full Game Vote History and Session IDs Without Authentication

A critical security vulnerability has been discovered in a game server's API, exposing the complete historical dataset of player votes, scores, and session identifiers to anyone on the internet. The `/api/export/votes.csv` endpoint lacks any form of authentication, allowing uncredentialed access to download the entire ...

The Lab · 2026-03-28 13:27:08 · GitHub Issues

2. Pingen API Security Flaw: Static Token Field Exposes Multi-Tenant Credential Sharing Risk

A critical security vulnerability has been identified in the Pingen API client library, where a static field declaration inadvertently shares authentication tokens across all client instances. In a multi-tenant application, this flaw means a single access token obtained for one organization (e.g., Organisation X) is au...